feat: implement issue #1232 — [bug] Phase 4 gate wiring ships to adopter stubs but agent-rate-limit-gate.sh is absent at v1 — gate is inert and fail-open - #1234
Conversation
…ter stubs but agent-rate-limit-gate.sh is absent at v1 — gate is inert and fail-open
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 38 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (4)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughThe initiative-driver rate-limit gate now uses pinned tooling and reports missing-script and invocation failures. The workflow remains fail-open for dispatch through ChangesInitiative-driver rate-limit gate
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix · Severity of issue fixed: Medium Merge Risk: ⚪ Minimal · up to The change pins the gate tooling to a reviewed commit and makes gate failures visible while dispatch stays fail-open. No concrete merge-blocking risk remains. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The immutable tooling pin improves integrity and failure visibility, but the workflow still lacks repository context for reading rate-limit history, so ordinary runs are expected to remain ungated. Increased exposure was not established; production token permissions and downstream behavior remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❓ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
Full details: Linked Issues checkExplanation The changes address the main coding requirements in [
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — waiting on PR blockers (intent: review-changes)PR: #1234 |
|
Note @don-petry I reviewed this PR and no code changes were needed, but I can't mark it done yet: required check |
There was a problem hiding this comment.
Code Review
This pull request pins the agent rate-limit gate tooling to a specific commit SHA instead of a moving tag, and adds robust error handling to fail loudly but open if the gate script is missing. It also introduces a new BATS test suite to verify these behaviors. The review feedback focuses on improving the reliability of these BATS tests by replacing generic negations and non-zero exit status checks with explicit assertions of the expected exit status, which prevents false positives from unrelated script errors.
|
No description provided. |
Superseded by automated re-review at
|
Superseded by automated re-review at
|
There was a problem hiding this comment.
All reported issues were addressed across 4 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
|
No description provided. |
Dev-Lead — fix-reviews (applied)Changes committed and pushed. Requested items addressed:
|
Superseded by automated re-review at
|
|
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: 8b8759dcd7a449971582286dba48b9d8aee7d302
Review mode: triage-approved (single reviewer)
Summary
Fixes #1232. The initiative-driver stub fetched the rate-limit gate tooling at tag v1, which does not contain agent-rate-limit-gate.sh, so the gate never ran. This PR pins the tooling checkout to a full commit SHA (cd0b167), passes --repo so the gate reads the caller's run history, and swaps the silent '|| true' for a loud failure that still lets the dispatch run (::error:: annotation, step summary, step marked failed, continue-on-error keeps dispatch going). It also corrects the header, documents the pin in agent-rate-limits.md, and adds a bats suite. The live copy and the standard are byte-identical (same blob 1c7c765b2). Every finding from the prior cascade review (at cd62129) is resolved at 8b8759d, and all required checks are green.
Linked issue analysis
#1232 acceptance criteria:
- Gate script resolves at the fetched ref: done. I confirmed that scripts/agent-rate-limit-gate.sh, scripts/lib/agent-rate-limit.sh and standards/agent-rate-limits.json all resolve at cd0b167, and that the gate parses
--repo(line 413). - Missing script is detected: done. A
[ -f ]guard emits ::error:: and a step-summary line and exits 1. Gate errors are surfaced too, through|| { rc=$?; ...; exit $rc; }. - Tooling checkout pinned: done. It uses a full SHA, with the bump procedure documented in agent-rate-limits.md.
- Header matches behaviour: done. The 'AHEAD of the cancel-in-progress' claim is removed, and adoption step 3 now names GH_PAT_DON_PETRY with GH_PAT_WORKFLOWS as fallback.
- Fan-out PRs regenerated: this is post-merge standards-sync work and can't be shown in this PR. See the note under Findings.
Findings
Prior review findings (cascade at cd62129):
- major, gate call missing
--repo: resolved. 8b8759d adds--repo "$ARL_TRACKING_REPO", the pinned gate supports it, and a bats test covers it. - major, CI pending on the new head: resolved. Every required check (SonarCloud, CodeQL, AgentShield, Detect ecosystems) is green at 8b8759d, and so are Lint, ShellCheck, bats, gitleaks and the Agent Security Scan.
- minor, the gate can still allow silently with exit 0 when run history can't be read: this is fail-open by design and documented. Not a regression; non-blocking.
- minor, the
decision=deferassertion in the missing-script test is weak: non-blocking test-quality nit.
New / remaining notes (non-blocking):
- nit: The stub header says the concurrency group 'cancels a superseded run before any step (gate included) executes'. agent-rate-limits.md now says, more accurately, that it 'may cancel a superseded run after its steps have started'. The two wordings should eventually agree. This is documentation only.
- info: The body says
Closes #1232, but acceptance criterion 5 (regenerating the stalled fan-out PRs) happens after merge via standards-sync. Whoever owns #1232 may want to confirm the fan-out PRs refresh before treating it as fully done. - info: Security posture improves. The PAT-bearing tooling checkout moves from a moving tag to an immutable SHA. The checkout action stays SHA-pinned, persist-credentials stays false, and untrusted values reach the script through
env:rather than${{ }}interpolation inrun:. No new secret surface. - Secret scan (MCP): the run_secret_scanning tool is not available in this environment, so it was skipped. The gitleaks CI check passed.
- All review threads (gemini-code-assist, cubic) are resolved, and there are no unanswered human questions.
CI status
All required checks pass at 8b8759d: SonarCloud, CodeQL, agent-shield / AgentShield and dependency-audit / Detect ecosystems. Lint, ShellCheck, bats, Lint and bats, Secret scan (gitleaks), Agent Security Scan, duplicate-decl-gate, Analyze (actions/python) and the AGENTS.md self-check also pass. Two runs are still queued: dependency-audit / npm audit (not required) and pr-auto-review / check-and-dispatch, which is this review's own run.
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 5.5 [opus 4.8, opus 4.7]). Reply if you need a human review.
|
pr-review approved on PARTIAL advisory evidence: 3/5 required advisory bots reported before the gate's head-age-timeout fallback proceeded. Recorded for the miss-rate metric (#1596). |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: 8b8759dcd7a449971582286dba48b9d8aee7d302
Review mode: triage-approved (single reviewer)
Summary
Confirms the triage assessment for #1232. The initiative-driver stub (canonical copy plus a byte-identical live copy) now checks out the gate tooling at a full commit SHA instead of the moving v1 tag, which did not contain the gate script. A missing script or a gate error now fails the gate step loudly (::error:: + step summary + non-zero exit) instead of being hidden by || true. continue-on-error keeps the dispatch fail-open. The step also passes --repo, and the header text is corrected. Note: the PR was already merged (2026-10-02T18:26:18Z) at this same head SHA, so this verdict is a confirmation only.
Linked issue analysis
Closes #1232. Acceptance criteria:
- Script resolves at the fetched ref: confirmed. Pinned SHA
cd0b1675…exists onmain(1 commit behind main) and all three gate files resolve there:scripts/agent-rate-limit-gate.sh,scripts/lib/agent-rate-limit.sh,standards/agent-rate-limits.json. - Missing script is detected: confirmed. An explicit
[ -f ]check emits ::error:: and exits 1, and a bats test runs the extracted step script to prove it. - Checkout is pinned: confirmed. It uses a full 40-char SHA, and the bump procedure is documented in
standards/agent-rate-limits.md. - Header matches behaviour: confirmed. The claim that the gate runs AHEAD of the concurrency group is removed, and adoption step 3 now names
GH_PAT_DON_PETRY. - Fan-out PRs regenerated: this happens through standards-sync after merge, so it is out of scope for this PR.
Findings
No blocking findings.
- Non-blocking (docs): the stub header says the concurrency group cancels a superseded run "before any step (gate included) executes".
standards/agent-rate-limits.mdsays it "may cancel a superseded run after its steps have started". The standards doc is the more accurate of the two, since cancel-in-progress cancels the earlier, possibly already-running, run. Consider making the wording match in a follow-up. - Verified: the gate script supports
--repo <owner/repo>(it is passed togh run list --repo), so the new flag is valid. - Verified:
|| { rc=$?; …; exit "$rc"; }correctly keeps the gate's exit code underset -e. - Security: no new secret handling. The PAT goes to first-party code at an immutable SHA, which is stronger than the moving tag it replaces.
persist-credentials: falseis kept, and theactions/checkoutpin is unchanged. - All review threads (gemini, cubic) are resolved, and there are no unanswered human questions.
CI status
All required checks pass: Lint, bats, ShellCheck, CodeQL (actions/python), SonarCloud (Quality Gate passed), gitleaks, AgentShield, Agent Security Scan, and dependency-audit. Some dev-lead orchestration jobs show CANCELLED or SKIPPED; these are superseded automation runs, not test failures.
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 5.5 [opus 4.8, opus 4.7]). Reply if you need a human review.



Problem
[bug] Phase 4 gate wiring ships to adopter stubs but agent-rate-limit-gate.sh is absent at v1 — gate is inert and fail-open
From the issue: Phase 4 (#640, PR #1059) wired the agent rate-limit gate into the
initiative-driver.ymlcaller stub. The stub fetches the gate tooling frompetry-projects/.githubat refv1.scripts/agent-rate-limit-gate.shdoes not exist atv1.v1isd3d768da, which is 359 commits behindmain, and the script is only onmain.Risk
Medium — changes GitHub Actions workflow behavior, which is exercised only post-merge; verify via the affected workflow runs.
Test plan
Tests added/updated:
test/workflows/initiative-driver/gate-tooling.bats. Verification:bash scripts/dev-lead-lint.sh(shellcheck --severity=warning) ran pre-commit; the bats suite runs in CI.Rollback
Revert this PR. No non-revertible side effects (no tags, migrations, or external state).
Monitoring
Watch the affected workflow run(s) in the Actions tab and this PR's Lint check for regressions.
Closes #1232